IP Library Granted Patent US 10,489,156
Granted Patent B2
US 10,489,156 · App. 15/656,798 · Granted Nov 26, 2019

Techniques to verify and authenticate resources in a data center computer environment

Inventors: Alberto J. Munoz (Los Altos, CA); Murugasamy K. Nachimuthu (Beaverton, OR); Mohan J. Kumar (Aloha, OR); Wojciech Powiertowski (Beaverton, OR); Sergiu D. Ghetie (Hillsboro, OR); Neeraj S. Upasani (Portland, OR); Sagar V. Dalvi (Hillsboro, OR); Chukwunenye S. Nnebe (Folsom, CA); Jeanne Guillory (Hillsboro, OR)
Assignee: INTEL CORPORATION
G06F9/30036B25J15/0014B65G1/0492G02B6/3882G02B6/3893G02B6/3897G02B6/4292G02B6/4452G05D23/1921G05D23/2039G06F1/183G06F3/061G06F3/064G06F3/067G06F3/0611G06F3/0613G06F3/0616G06F3/0619G06F3/0625G06F3/0631G06F3/0638G06F3/0647G06F3/0653G06F3/0655G06F3/0658G06F3/0659G06F3/0664G06F3/0665G06F3/0673G06F3/0679G06F3/0683G06F3/0688G06F3/0689G06F8/65G06F9/3887G06F9/4401G06F9/505G06F9/5016G06F9/5044G06F9/5072G06F9/5077G06F9/544G06F11/141G06F11/3414G06F12/0862G06F12/0893G06F12/10G06F12/109G06F12/1408G06F13/161G06F13/1668G06F13/1694G06F13/409G06F13/4022G06F13/4068G06F13/42G06F13/4282G06F15/8061G06F16/9014G06Q10/06G06Q10/06314G07C5/008G08C17/02G11C5/02G11C5/06G11C7/1072G11C11/56G11C14/0009H03M7/30H03M7/3084H03M7/3086H03M7/40H03M7/4031H03M7/4056H03M7/4081H03M7/6005H03M7/6023H04B10/2504H04L9/0643H04L9/14H04L9/3247H04L9/3263H04L12/2809H04L29/12009H04L41/024H04L41/046H04L41/082H04L41/0813H04L41/0896H04L41/145H04L41/147H04L43/08H04L43/0817H04L43/0876H04L43/0894H04L43/16H04L45/02H04L45/52H04L47/24H04L47/38H04L47/765H04L47/782H04L47/805H04L47/82H04L47/823H04L49/00H04L49/15H04L49/25H04L49/357H04L49/45H04L49/555H04L67/02H04L67/10H04L67/1004H04L67/1008H04L67/1012H04L67/1014H04L67/1029H04L67/1034H04L67/1097H04L67/12H04L67/16H04L67/306H04L67/34H04L69/04H04L69/329H04Q1/04H04Q11/00H04Q11/0003H04Q11/0005H04Q11/0062H04Q11/0071H04W4/023H05K1/0203H05K1/181H05K5/0204H05K7/1418H05K7/1421H05K7/1422H05K7/1447H05K7/1461H05K7/1487H05K7/1489H05K7/1491H05K7/1492H05K7/1498H05K7/2039H05K7/20709H05K7/20727H05K7/20736H05K7/20745H05K7/20836H05K13/0486G06F2209/5019G06F2209/5022G06F2212/1008G06F2212/1024G06F2212/1041G06F2212/1044G06F2212/152G06F2212/202G06F2212/401G06F2212/402G06F2212/7207G06Q10/087G06Q10/20G06Q50/04G08C2200/00H04B10/25H04L41/12H04L41/5019H04L43/065H04Q2011/0037H04Q2011/0041H04Q2011/0052H04Q2011/0073H04Q2011/0079H04Q2011/0086H04Q2213/13523H04Q2213/13527H04W4/80H05K7/1485H05K2201/066H05K2201/10121H05K2201/10159H05K2201/10189Y02D10/14Y02D10/151Y02P90/30Y10S901/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,489,156
App. No.
15/656,798
Granted
Nov 26, 2019
Kind
B2
Abstract

Embodiments are generally directed apparatuses, methods, techniques and so forth to receive a sled manifest comprising identifiers for physical resources of a sled, receive results of an authentication and validation operations performed to authenticate and validate the physical resources of the sled, determine whether the results of the authentication and validation operations indicate the physical resources are authenticate or not authenticate. Further and in response to the determination that the results indicate the physical resources are authenticated, permit the physical resources to process a workload, and in response to the determination that the results indicate the physical resources are not authenticated, prevent the physical resources from processing the workload.

Claims (65)

1. An apparatus, comprising:

a processor; and

memory comprising instructions for a pod management controller that when executed by the processor cause the processor to:

determine whether a sled manifest and results are authentic and valid, the results generated by an authentication and validation operation performed to authenticate and validate physical resources of a sled, the authentication and validation operation to generate a nonce, communicate the nonce to at least one of the physical resources of the sled, and authenticate a signed version of the nonce received from the at least one physical resource in response;

determine whether the results of the authentication and validation operation indicate the physical resources are authentic and valid;

permit the physical resources to process a workload in response to a determination that the sled manifest and results are authentic and valid, and the results indicate the physical resources are authentic and valid; and

prevent the physical resources from processing the workload in response to a determination that at least one of the sled manifest is not authentic and valid, the results are not authentic and valid, and the results indicate the physical resources are not authentic and valid.

2. The apparatus of claim 1 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to:

receive the sled manifest comprising identifiers for the physical resources from the sled; and

receive the results of the authentication and validation operation performed to authenticate and validate the physical resources from the sled.

3. The apparatus of claim 1 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to authenticate the sled manifest using a public key, the public key obtained from an original manufacturer of the sled or a trusted third party.

4. The apparatus of claim 1 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to:

generate a hash value based on the sled manifest;

compare the hash value with another hash value communicated with the results;

validate the sled manifest when the hash value and the other hash value match; and

invalidate the sled manifest when the hash value and the other hash value do not match.

5. The apparatus of claim 1 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to authenticate the results using a public key, the public key obtained from the sled manifest.

6. The apparatus of claim 1 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to add an indication of the physical resources in a database to permit the physical resources to process the workload.

7. The apparatus of claim 1 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to receive the sled manifest and the results of the authentication and verification operations via a secure link with the sled.

8. The apparatus of claim 1 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to generate a composed node comprising at least one of the physical resources of the sled.

9. The apparatus of claim 1 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to:

send a platform certificate request to generate a platform certificate for a composed node to a certificate authority, the platform certificate to identify physical resources including the at least one of the physical resources used for the composed node; and

receive a signed platform certificate.

10. The apparatus of claim 9 , the memory comprising instructions for the pod management controller that when executed by the processor cause the processor to send the signed platform certificate for the composed node to a client device.

11. A non-transitory computer-readable storage medium, comprising a plurality of instructions, that when executed, enable processing circuitry to:

determine whether a sled manifest and results are authentic and valid, the results generated by an authentication and validation operation performed to authenticate and validate physical resources of a sled, the authentication and validation operation to generate a nonce, communicate the nonce to at least one of the physical resources of the sled, and authenticate a signed version of the nonce received from the at least one physical resource in response;

determine whether the results of the authentication and validation operation indicate the physical resources are authentic and valid;

permit the physical resources to process a workload in response to a determination that the sled manifest and results are authentic and valid, and the results indicate the physical resources are authentic and valid; and

prevent the physical resources from processing the workload in response to a determination that at least one of the sled manifest is not authentic and valid, the results are not authentic and valid, and the results indicate the physical resources are not authentic and valid.

12. The non-transitory computer-readable storage medium of claim 11 , comprising a plurality of instructions, that when executed, enable processing circuitry to:

receive the sled manifest comprising identifiers for the physical resources from the sled; and

receive the results of the authentication and validation operation performed to authenticate and validate the physical resources from the sled.

13. The non-transitory computer-readable storage medium of claim 11 , comprising a plurality of instructions, that when executed, enable processing circuitry to authenticate the sled manifest using a public key, the public key obtained from an original manufacturer of the sled or a trusted third party.

14. The non-transitory computer-readable storage medium of claim 11 , comprising a plurality of instructions, that when executed, enable processing circuitry to:

generate a hash value based on the sled manifest;

compare the hash value with another hash value communicated with the results;

validate the sled manifest when the hash value and the other hash value match; and

invalidate the sled manifest when the hash value and the other hash value do not match.

15. The non-transitory computer-readable storage medium of claim 11 , comprising a plurality of instructions, that when executed, enable processing circuitry to authenticate the results using a public key, the public key obtained from the sled manifest.

16. The non-transitory computer-readable storage medium of claim 11 , comprising a plurality of instructions, that when executed, enable processing circuitry to add an indication of the physical resources in a database to permit the physical resources to process the workload.

17. The non-transitory computer-readable storage medium of claim 11 , comprising a plurality of instructions, that when executed, enable processing circuitry to receive the sled manifest and the results of the authentication and verification operations via a secure link with the sled.

18. The non-transitory computer-readable storage medium of claim 11 , comprising a plurality of instructions, that when executed, enable processing circuitry to generate a composed node comprising at least one of the physical resources of the sled.

19. The non-transitory computer-readable storage medium of claim 11 , comprising a plurality of instructions, that when executed, enable processing circuitry to:

send a platform certificate request to generate a platform certificate for a composed node to a certificate authority, the platform certificate to identify physical resources including the at least one of the physical resources used for the composed node; and

receive a signed platform certificate.

20. The non-transitory computer-readable storage medium of claim 19 , comprising a plurality of instructions, that when executed, enable processing circuitry to send the signed platform certificate for the composed node to a client device.

21. A computer-implemented method to verify and authentic physical resources, comprising:

determining whether a sled manifest and results are authentic and valid, the results generated by an authentication and validation operation performed to authenticate and validate physical resources of a sled, the authentication and validation operation to generate a nonce, communicate the nonce to at least one of the physical resources of the sled, and authenticate a signed version of the nonce received from the at least one physical resource in response;

determining whether the results of the authentication and validation operation indicate the physical resources are authentic and valid;

permitting the physical resources to process a workload in response to a determination that the sled manifest and results are authentic and valid, and the results indicate the physical resources are authentic and valid; and

preventing the physical resources from processing the workload in response to a determination that at least one of the sled manifest is not authentic and valid, the results are not authentic and valid, and the results indicate the physical resources are not authentic and valid.

22. The computer-implemented method of claim 21 , comprising:

receiving the sled manifest comprising identifiers for the physical resources from the sled;

authenticating the sled manifest using a public key, the public key obtained from an original manufacturer of the sled or a trusted third party; and

receiving the results of the authentication and validation operation performed to authenticate; and

authenticating the results using a public key, the public key obtained from the sled manifest and validating the physical resources from the sled.

23. The computer-implemented method of claim 21 , comprising:

generating a hash value based on the sled manifest;

comparing the hash value with another hash value communicated with the results;

validating the sled manifest when the hash value and the other hash value match; and

invalidating the sled manifest when the hash value and the other hash value do not match.

24. The computer-implemented method of claim 21 , comprising:

adding an indication of the physical resources in a database to permit the physical resources to process the workload.

25. The computer-implemented method of claim 21 , comprising:

generating a composed node comprising at least one of the physical resources of the sled.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2018
From: MUNOZ, ALBERTO J.; NACHIMUTHU, MURUGASAMY K.; KUMAR, MOHAN J.; POWIERTOWSKI, WOJCIECH; GHETIE, SERGIU D.; UPASANI, NEERAJ S.; DALVI, SAGAR V.; NNEBE, CHUKWUNENYE S.; GUILLORY, JEANNE
To: INTEL CORPORATION
Reel/Frame 045161/0904 →
Continuity (4)
Provisional Application 62365969 · Jul 22, 2016
Provisional Application 62376859 · Aug 18, 2016
Provisional Application 62427268 · Nov 29, 2016
Related Publication 20180026800A1 · Jan 25, 2018
Cited By (5)
US 12,261,940 US 12,288,101 US 12,506,817 US 12,619,465 US 12,671,589